Google Search

Showing posts with label breach. Show all posts
Showing posts with label breach. Show all posts

Tuesday, September 23, 2014

Home Depot Investigates Possible Data Breach

US home-improvement retailer Home Depot is investigating “unusual activity” regarding its customer data, following a report by investigative security journalist Brian Krebs that the company may have suffered a payment-card breach that started in April or May and that may affect all 2,200 US stores. He discovered details about the incident from a posting on a black market forum. Home Depot spokeswoman Paula Drake said if the company confirms that a breach has occurred, it will notify customers immediately. Krebs noted that it appears the hackers responsible “may be the same group of Russian and Ukrainian hackers responsible for [earlier] data breaches at Target, Sally Beauty, and P.F. Chang’s, among others.” . If the breach indeed began in late April or early May 2014, he added, “and if even a majority of Home Depot stores were compromised, this breach could be many times larger than [the] Target [incident], which had 40 million credit and debit cards stolen over a three-week period.” (BBC)(Krebs on Security)


View the original article here

Tuesday, June 3, 2014

Target CEO Resigns amid Continuing Data Breach Fallout

Department-store chain Target’s board of directors has announced the resignation of CEO Gregg Steinhafel, the latest move to occur in the wake of the huge 2013 data breach from which the company is still recovering. Steinhafel, a 35-year Target employee of the company who also served as its president and a board member, had said that he held himself personally accountable for the data breach. Chief financial officer John Mulligan is acting as interim CEO and president, and board member Roxanne S. Austin will serve as non-executive board chair. Steinhafel remains with Target in an advisory capacity. During the December 2013 breach, hackers stole credit- or debit-card information on up to 110 million people who purchased items at Target. Since then, Target has reported that its revenue during the Christmas 2013 shopping quarter was 5 percent less than in 2012. The company also reported paying $61 million in hacking-related expenses, with insurance covering $17 million. The company plans to use chip-and-pin technology from MasterCard in its new company-branded credit and debit cards, due for release in early 2015. (The Los Angeles Times)(Businessweek)(USA Today)(Target)


View the original article here

Thursday, March 6, 2014

Hackers Breach Casino Sites

Hackers breached and defaced all the websites of Las Vegas Sands Corp., including the home pages for some of the world’s largest casinos. After the attack, the company down the sites, which includes those for the company, the Venetian and Palazzo casinos in Las Vegas, and the Sands casinos in Bethlehem, Pennsylvania, Singapore, and Macau. The attackers also stole and released some Sands employees’ personal information, including Social Security numbers, email addresses, and job titles. Company officials are still assessing the damages. Experts guess the attacks may have been politically motivated, as the hackers placed a photo of Sands CEO Sheldon Adelson posing with Israel Prime Minister Benjamin Netanyahu on the affected websites with a message condemning the use of weapons of mass destruction on the sites. Adelson, whose personal wealth is estimated to be at least $37 billion, is a vocal supporter of Israel and has met Netanyahu several times. He has also sought to have Internet gambling banned in the US. The Nevada State Gaming Control Board is investigating the breach. (Associated Press)(The Morning Call)


View the original article here

Saturday, June 2, 2012

Zappos breach goes beyond credit cards: Consumers face identity theft if hackers correlate other penetrated databases

ScienceDaily (Jan. 18, 2012) — Stephen B. Wicker, Cornell professor of Electrical and Computer Engineering at Cornell University, comments on the Zappos web site breach by hackers.

Wicker conducts research in wireless information networks. He focuses on networking technology, law, and sociology, and how regulation can affect the privacy and speech rights. He is the author of the book "Cellular Convergence and the Death of Privacy," to be published by Oxford University Press at the end of 2012.

He says: "Though Zappos has not stated how security was breached, this event is a reminder that security is not a fix or an overlay, it is an ongoing process that must be intrinsic to the design and maintenance of an Internet presence.

"Zappos said that credit card information was not stolen, but acknowledged that email addresses, billing and shipping addresses, phone numbers, and the last four digits from credit cards may have been compromised. This is a lopsided outcome for the customer.

"The bigger problem Zappos faces is that large databases of consumer information can be used for identity theft. As Zappos acknowledged, users who use the same or similar passwords are at risk of theft through access to other sites such as Amazon or Ebay.

"More generally, information about a customer can be used to 'de-anonymize' other databases on other Web sites, further invading customer privacy. Correlation attacks enabled by such data have been shown to strip anonymity from NetFlix, AOL and other databases that were assumed safe. Thus, the information used can include customer preferences, beliefs and practices that are far harder to change than a credit card number.

"Zappos' response is admirable for its forthrightness and immediacy, but this is a reminder of the risk run when online service providers maintain databases of user data. This is a practice that many, many web site and service providers engage in for convenience and, in some cases, for profit. This is a practice that a networked society cannot afford for the long term if individual privacy is to be preserved."

Share this story on Facebook, Twitter, and Google:

Other social bookmarking and sharing tools:

Story Source:

The above story is reprinted from materials provided by Cornell University, via Newswise.

Note: Materials may be edited for content and length. For further information, please contact the source cited above.

Note: If no author is given, the source is cited instead.

Disclaimer: Views expressed in this article do not necessarily reflect those of ScienceDaily or its staff.


View the original article here